Annex III Is the Question, Not the Answer
The AI Act reaches high-risk classification by two roads. One runs through Article 6(1): your AI is a safety component of a product already regulated under EU law — machinery, medical devices, lifts — and that product needs third-party conformity assessment. The other runs through Article 6(2): your system’s intended purpose falls under one of the use cases listed in Annex III, the familiar list that includes recruitment, creditworthiness, education, essential services and biometrics.
Here is what almost every summary leaves out. Landing in Annex III does not settle the classification. Article 6(3) says an Annex III system “shall not be considered to be high-risk” where it does not pose a significant risk of harm to health, safety or fundamental rights — including by not materially influencing the outcome of decision-making. It is a genuine derogation, and it is the difference between a compliance programme and a Tuesday afternoon.
So the useful question is not “am I in Annex III?” It is: “I am in Annex III — can I rebut the presumption, and what does rebutting it cost?” The rest of this article answers that. If you want the four risk tiers and the broader picture first, that is the subject of our plain-terms guide to the AI Act; this piece goes one level down, into the classification decision itself.
The Article 6(3) Filter: A Chapeau and Four Conditions
The filter is often described as “four exemptions.” That description costs people money, because it hides the structure. There are two hurdles, and you must clear both.
The first is the chapeau: the system must not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making. The second is that at least one of four conditions applies. The system is intended to perform a narrow procedural task; or to improve the result of a previously completed human activity; or to detect decision-making patterns or deviations from prior patterns without being meant to replace or influence the previously completed human assessment absent proper human review; or to perform a preparatory task to an assessment relevant to an Annex III use case.
Both hurdles, not either. A system can plainly perform a preparatory task and still fail the filter because that preparatory task materially shapes what the human decides afterwards.
Profiling overrides all four conditions
This is the sentence that ends most exemption hopes, and it is easy to miss because it sits after the list rather than before it: notwithstanding the conditions, an Annex III system is always high-risk where it performs profiling of natural persons. Not “weighed against” the four conditions — it overrides them.
Profiling is not a term the AI Act invents; it borrows the GDPR’s definition, which is broad: automated processing of personal data to evaluate personal aspects of a person, particularly to analyse or predict performance at work, economic situation, reliability, behaviour and so on. Read that definition next to a CV-ranking tool and the argument is over before it starts. If your system is in Annex III and evaluates people, the filter is simply not available to you. Everything else is a detail.
“Narrow” is meant narrowly
The Commission published draft guidelines on high-risk classification on 19 May 2026, with the consultation closing on 23 June 2026. They are not binding, and the final version is expected before the obligations bite — but market surveillance authorities will lean on them, and they are explicit that the Article 6(3) conditions must be read narrowly, because they are exceptions to a fundamental-rights protection.
“Narrow procedural task” means things like converting a data format, sorting incoming documents into predefined categories, or flagging duplicate records — work that is clearly defined and limited, and that does not evaluate, score or rank what it processes. The moment your “narrow procedural task” starts assigning a fit score, it is not narrow and it is not procedural. A generous reading here is not a strategy; it is an unbooked liability.
The Exemption Is Paperwork, Not Silence
The common mental model is that the filter makes the AI Act go away for that system. It does not. Article 6(4) is explicit: a provider who concludes that an Annex III system is not high-risk must document that assessment before the system is placed on the market or put into service, must comply with the registration obligation in Article 49(2), and must hand the documentation to national authorities on request.
So claiming the exemption is an affirmative act with a paper trail, made before you ship, not a defence you improvise during an inspection. You are on record. If your reasoning is thin, you have helpfully written it down for the authority.
This nearly changed. The Commission’s Digital Omnibus on AI proposed removing the registration duty for systems exempted under Article 6(3). During negotiations that proposal was dropped. The package agreed on 7 May 2026 and given the Council’s final green light on 29 June 2026 keeps the registration obligation, with a simplified procedure — some fields of Annex VIII, Section B fall away, but the entry does not. Anyone who planned around the draft got a surprise.
Why This Lands on You, Not Your Vendor
Read Article 6(4) again: the duty falls on the provider. Most mid-sized companies reasonably assume they are deployers — they buy the tool, someone else built it, so someone else carries the provider duties. Frequently true. Frequently not, and this is where projects get caught.
Article 25 flips the role. A deployer, distributor or importer becomes the provider of a high-risk system if they put their own name or trademark on it, if they make a substantial modification to it, or if they modify its intended purpose so that it becomes high-risk under Article 6. Commission a bespoke application-screening tool, run it under your own brand, and you are not the deployer of someone else’s product — you are the provider of your own. The Article 6(3) assessment, the documentation, and the registration are yours.
The third trigger deserves particular attention, because it is the one nobody notices. A general-purpose model or an off-the-shelf tool that was never high-risk becomes high-risk when you point it at an Annex III purpose. Your vendor did nothing wrong and changed nothing. The classification moved because of what you decided to use it for. The works council conversation tends to arrive at the same moment, for the same reason.
The Classification Is an Architecture Decision
Here is the part I care about as an engineer rather than a reader of statutes: whether you land inside or outside Annex III’s high-risk tier is usually decided by how the system is built, not by how the project is described.
Take a concrete case. A 400-person automotive supplier gets far more applications than its two-person HR team can read, and wants AI to help. That single sentence can become two very different systems.
Design A: the system reads each CV and returns a fit score, ranking candidates so HR starts at the top. This is Annex III recruitment, it evaluates people, it is profiling, it materially influences the outcome. High-risk, no filter, no argument. Perfectly legal — but you are now building a conformity-assessed system with risk management, data governance and logged human oversight, and that is a different budget and a different timeline.
Design B: the system extracts structured fields from each CV into the applicant tracking system — name, qualifications, languages, years in role — flags duplicate applications, and converts attachments to a consistent format. It does not score. It does not rank. It does not sort by suitability. Humans read every application, in the order they always did, with the tedious transcription already done. That is a narrow procedural task, it does not evaluate anybody, and it does not shape the decision.
Same use case, same department, same budget line, opposite classification. What separated them was not a legal opinion. It was the choice to output fields instead of a score. Design B is also, unromantically, where most of the actual time went: nobody was reading 300 CVs slowly because ranking was hard; they were reading them slowly because typing things into the ATS was.
December 2027 Is Not the Relief It Looks Like
The Digital Omnibus pushed the high-risk obligations back. Stand-alone Annex III systems now apply from 2 December 2027; high-risk AI embedded in products regulated under Annex I follows on 2 August 2028. The same package also narrowed “safety component,” so AI that only assists users, optimises performance or handles non-safety quality control does not become high-risk merely by sitting inside a regulated product, unless its failure would endanger health or safety. Note what did not move: the prohibitions have applied since February 2025 and the general-purpose AI obligations since August 2025.
The extra eighteen months are real, and if you operate high-risk systems you should use them. But they are not a reason to defer the classification question, for a plain engineering reason: the classification is fixed by design decisions you are making now, and the deadline governs when the system must comply, not when you get to choose. A system shipping in 2026 that scores applicants is already on the wrong side of a line that becomes enforceable while it is still in production. Retrofitting risk management, data governance and logged oversight into a live system is the most expensive way to arrive at compliance — and if you have ever tried to reconstruct what a model did eighteen months ago, you already know that the record-keeping has to be designed in from the start. The deadline you should care about is not December 2027; it is the architecture review you are doing this quarter.
Where Tippel Fits
None of this is legal advice, and I am not your lawyer — for a system near the line, get one. But most of the classification question is not a legal question. It is a question about what your system outputs, what it touches, and whether a human decision depends on it. Those are engineering facts, and they are settled at design time, by whoever is writing the code.
That is the part I can help with: building the system so the classification is obvious rather than arguable, and writing the Article 6(3) assessment as a byproduct of the design rather than as an archaeology project afterwards. When the decision is documented as it is made, the paperwork is a filing exercise. When it is reconstructed two years later from a repository and some memories, it is a project. The same discipline shows up when you have to write acceptance criteria into a Werkvertrag — decide it up front, in writing, or argue about it later.
If you want a straight read on which of your AI uses are anywhere near Annex III and which are comfortably nowhere near it, that is part of the AI Readiness Check. If you would rather just talk it through, get in touch.